Skip Navigation
BlackBerry Blog

86 Percent of Consumers Never Update Their Router’s Firmware

Broadband Genie recently published survey results about router security that are both depressing and entirely unsurprising. The most alarming findings are that 86% of survey respondents have never updated their router’s firmware and 82% of respondents have never changed their administrator password.

Broadband Genie wrote that not changing the administrative password is risky, “as the default passwords are often insecure and shared across all routers of that brand or model range. A significant number have also never updated the firmware and could be vulnerable to known security exploits.”

They also commented: “Perhaps most concerning, 51% say they have never carried out any of the actions listed, potentially leaving them open to all manner of security and reliability issues affecting their broadband and any devices connected to the router.”

*Image source: Broadband Genie

Are any of these results surprising? No. But we’d like to assert that the problem isn’t the users and consumers; the problem lies with the technology vendors, who should be held responsible for the security of their technology. Are we really expecting the average user to go through a task list of updates and manage administrative settings in order to secure themselves?

We find ourselves asking this question often, not just of router security of course, but for almost all consumer-targeted technology, especially in the age of the Internet of Things (IoT). We all acknowledge that consumers shouldn’t be expected to be security experts, and yet not much has changed within the industry to safeguard them from security gaps. Rather than build products that are secure by default, we expect users to go through often poorly written technical documentation to apply best practices that they may not fully understand.

Best practices haven’t changed for decades, so why isn’t it just done by default? Hardcoded passwords are bad yet they are still plague Internet-connected devices on the market, setting the stage for another Mirai-like botnet. Instead, the tendency is to make a profit from the failings of unpatched, unsecured technology by selling yet more products to safeguard consumers from the unsecured devices the industry is selling them.

  • Users should not be responsible updating the firmware on their device. The device should automatically apply security updates.
  • Users shouldn’t have to change the Wi-Fi network name or password. Devices should automatically negotiate and connect through simpler methods.
  • Users shouldn’t have to change the administrator password. The device shouldn’t have a hardcoded administrator password.
  • Users shouldn’t have to check to see what devices are connected to the network. The network should be secure by default rather than open for anyone to connect.

It’s time we stop telling millions of users to apply best practices and start holding technology vendors responsible for the products they sell. If their technology was any good, it should work “like magic” without user intervention.

Jeffrey Tang

About Jeffrey Tang

Senior Security Researcher at Cylance

Jeffrey Tang is a Senior Security Researcher at Cylance focused on operating systems and vulnerability research. He started his career as a Global Network Exploitation & Vulnerability Analyst at the National Security Agency, where he conducted computer network exploitation operations in support of national security requirements. Prior to Cylance, Jeff served as the Chief Scientist at VAHNA to develop a security platform for identifying targeted network intrusions, and also worked as a CNO Developer at ManTech where he researched tools, techniques and countermeasures in computer network vulnerabilities.

Jeff completed his Bachelor of Science (BSc) in Electrical Engineering and Computer Science at the University of California, Berkeley and a Master of Science (MSc) in Offensive Computer Security at Eastern Michigan University.

The Cylance Research and Intelligence Team

About The Cylance Research and Intelligence Team

Exploring the boundaries of the information security field

The Cylance Research and Intelligence team explores the boundaries of the information security field identifying emerging threats and remaining at the forefront of attacks. With insights gained from these endeavors, Cylance stays ahead of the threats.